Acronis has published a checklist defining six required capabilities for MSP ransomware protection services, spanning exposure reduction, early detection, round-the-clock incident response, isolated backup preservation, clean recovery, and consistent enforcement across all client tenants. The guidance draws on Acronis's Cyberthreats Report, which documented 143 ransomware victims among MSPs, IT service providers and telecoms in 2025, with phishing responsible for 52% of initial breaches and unpatched systems for 27%.
New research from SentinelOne and Mimecast shows attackers are increasingly turning to employees with legitimate network access rather than relying solely on phishing or exploiting software flaws. SentinelOne found insider incidents now cost organizations an average of $19.5 million annually, with breaches involving privileged malicious insiders averaging $4.9 million per event. Mimecast separately reported a 42% year-over-year rise in malicious insider incidents.
Berlin officials confirmed cybercriminals are attempting to extort the city after the Rhysida ransomware gang publicly listed it on their leak site last Friday, following an intrusion discovered in mid-August. The attackers claim to have stolen nearly 1.44 million files totaling 5.79TB, including government, legal, financial, HR, and health records, along with credentials belonging to senior officials and infrastructure security assessments. Mayor Kai Wergner said Berlin will not pay, and law enforcement including the State Criminal Police Office and federal security agencies are investigating.
The ATF confirmed a cyberattack on a standalone system separate from its main network, formally classifying it as a 'major incident' that requires notifying Congress within a week. An ATF spokesperson said the affected system held sensitive data, including targets of ATF investigations. The Qilin ransomware gang has claimed responsibility on its leak site, though it has not published proof such as stolen data samples.
The ATF acknowledged that a standalone system separate from its main network was compromised, calling it a 'major incident' after the Qilin ransomware gang listed the agency on its dark web leak site. The agency said the affected system does not connect to its enterprise network or eForms platform, and is now working with the Department of Justice to investigate the breach.
NCC Group's July threat advisory reports a 22% month-over-month rise in ransomware activity, with 894 victim organization listings recorded across industrial, consumer services, technology, critical infrastructure, finance and healthcare sectors. The Gentlemen and Quilin topped the list of attributed groups, while the US accounted for 41% of incidents; notably, the month also saw the first fully agentic AI-driven ransomware attack chain and a breach at Ernst & Young claimed by ShinyHunters.
Researchers have identified a sophisticated malware toolkit called SynkLoader that revives an old screen-hijacking technique to steal passwords while also incorporating a range of newer capabilities. The malware supports multiple languages and functions as a multitool, suggesting it could serve as a precursor to ransomware deployment.